claude-md-writer
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read external, potentially untrusted project files to generate documentation, which creates an indirect prompt injection surface. Ingestion points: The instructions in SKILL.md direct the agent to read the README, package.json, CI config, and git logs within the repository. Boundary markers: The skill does not provide delimiters or specific instructions to ignore embedded commands or instructions within the files being read. Capability inventory: The skill environment allows the use of powerful tools including Read, Write, Edit, Glob, Grep, and Bash. Sanitization: There is no evidence of input validation or sanitization procedures for the data extracted from the project files.
Audit Metadata